Hello MArcel, thanks for your answer, we see that firewall block dhcp answer as spoofing, discover phase send from one vlan and answer go back to gateway vlan.
Now we remove antispoofing on firewall gateway vlan and all works, but is there any alternative solution on controller?
an 8 10:00:53 dhcpdwrap[3743]: <202534> <3743> <DBUG> |dhcpdwrap| |dhcp| Datapath vlan1306: DISCOVER 66:d0:b2:3c:fe:8e Transaction ID:0x7faa7c18 Options 35:01 3d:0166d0b23cfe8e 39:05dc 3c:616e64726f69642d646863702d3130 0c:696e736563757265 37:0103060f1a1c333a3b2b
Jan 8 10:00:53 dhcpdwrap[3743]: <202523> <3743> <DBUG> |dhcpdwrap| |dhcp| dhcprelay: mac=66:d0:b2:3c:fe:8e dev=eth1, length=296, from_port=68, op=1, giaddr=0.0.0.0, packet_vlan1306
Jan 8 10:00:53 dhcpdwrap[3743]: <202532> <3743> <DBUG> |dhcpdwrap| |dhcp| got 1 relay servers
Jan 8 10:00:53 dhcpdwrap[3743]: <202533> <3743> <DBUG> |dhcpdwrap| |dhcp| Relayed: DISCOVER server=10.5.4.56 giaddr=10.4.6.249 MAC=66:d0:b2:3c:fe:8e
Jan 8 10:00:53 dhcpdwrap[3743]: <202541> <3743> <DBUG> |dhcpdwrap| |dhcp| Received DHCP packet from Datapath, Flags 0x42, Opcode 0x5a, Vlan 1300, Ingress local, Egress 0/0/2, SMAC 00:1a:1e:06:0b:90